Commit 1ba789a
committed
EDGAPIUTL-38: Bump tomcat, jackson, netty, log4j, spring boot fixing vulns
https://folio-org.atlassian.net/browse/EDGAPIUTL-38
Fix multiple security vulnerabilities by bumping the spring boot dependencies from 4.0.5 to 4.0.6
and aws ssm from 2.41.27 to 2.42.41:
* https://www.cve.org/CVERecord?id=CVE-2026-34500 – tomcat
* https://app.snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-15907550 – jackson
* https://www.cve.org/CVERecord?id=CVE-2026-33871 – netty
* https://www.cve.org/CVERecord?id=CVE-2026-34480 – log4j
* https://www.cve.org/CVERecord?id=CVE-2026-34478 – log4j
* https://www.cve.org/CVERecord?id=CVE-2026-40973 – spring boot
* https://www.cve.org/CVERecord?id=CVE-2026-34477 – log4j
* https://www.cve.org/CVERecord?id=CVE-2026-40977 – spring boot
* https://www.cve.org/CVERecord?id=CVE-2026-40975 – spring boot
* https://www.cve.org/CVERecord?id=CVE-2026-40974 – spring boot1 parent 8cdec7b commit 1ba789a
1 file changed
Lines changed: 4 additions & 11 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
44 | 43 | | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | 44 | | |
51 | | - | |
52 | 45 | | |
53 | 46 | | |
54 | 47 | | |
| |||
0 commit comments